CVE-2026-5974 is an operating system command injection vulnerability affecting FoundationAgents MetaGPT versions up to 0.8.1, specifically in the Bash.run function within the metagpt/tools/libs/terminal.py library. The flaw allows attackers to execute arbitrary system commands through the vulnerable function. The vulnerability carries a CVSS 3.1 score of 7.3 (HIGH) with a network-based attack vector requiring no authentication or user interaction. Attack complexity is low, and successful exploitation could result in confidentiality, integrity, and availability impacts to the affected system. The EPSS score of 0.0176 indicates relatively low probability of exploitation in the wild compared to other known vulnerabilities. There is currently no evidence of active exploitation, and the vulnerability does not appear on the Known Exploited Vulnerabilities (KEV) catalog. The project maintainers were notified early through a pull request but have not yet taken responsive action. Community attention remains low, suggesting limited public awareness of this issue at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.8.1CPE matchmatch criteria | cpe:2.3:a:deepwisdom:metagpt:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.